Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:9c7e52533c5dd42a8a76508ef025f846a83776887ec66cb7e2d79352a3518c82

Manifest digest:

sha256:1dc33aba31c05f57c9a47cdcf8c68c2d53090ed19aae30c0abd15868164a9f07

Size

476.21 MB

Last pushed

4 hours ago

Vulnerabilities

0
12
21
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:f4af5ace1d4c695256b748318eb6acf9e076ebc1161eaa657cbcd8dc069c7ec7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:d03699f49691295bcccb5e6b9df27146401ad4164680f4c6b306842700de81ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:4b7f336734a7939451e5b53989b3b18e845e3ac9ba16447fa69f1818d864ac21
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:e1f2e1dd867b324a9e869caad847a3f7586a156e9f9b96447e7ed828985b81e3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:2e6bf03a4f8e30ac9e7087923b70586b635160c622d17883abed97f5174ebbe9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:d56608e7762bd03b8b855e0cd053ec44190a7e8f028ab31112c1b72c58230b8f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:10cc1c12912050566dec42903ac8711b0296aa953c35e33a5bbee251860741e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:782c673eb4e3885a7a28aa6c6d0560e97d185b2ed746f970ccebeea46805f42d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:9b2af1abd41d6eb08420db727d0bb7a8725319316cfbdce0ffb21ba2042b2ead
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:430e91165168a546922571a499915b634098350200c0da81b4c71d32edd796bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:43a30b9a1f1ffaec06189e7ec83826a42b1f3e069ee664c238ee17ccda1c65bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:047546ca4a12fc8a42f97904b8d60dae1bdc28ca8f5a016ef85fcca773ad5e33
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:85e15841278849c1ef840718c3cd0696b2cb43cd79e4dac5dff7f4c593bbd36e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:b887ec1527bead692578e19f08a87a45ac95f56aff2ed7e4251b1f7d4d3146e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:997de4d79c5705d90238c1d80bf07e86c44c911a2cd64bc259612766c6db7519